SB2019120431 - Multiple vulnerabilities in Keycloak



SB2019120431 - Multiple vulnerabilities in Keycloak

Published: December 4, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019120431
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper Authentication (CVE-ID: CVE-2019-14910)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.


2) Improper Authentication (CVE-ID: CVE-2019-14909)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.


Remediation

Install update from vendor's website.